# Hugging Face MCP Server

> Hugging Face MCP Server is an officially published MCP server from Hugging Face. Anomity scores its risk at 20 out of 100 (low).

- **Canonical URL:** https://catalog.anomity.ai/mcp/hugging-face-mcp-server
- **Kind:** MCP server
- **Publisher:** Hugging Face
- **Trust level:** official
- **Risk score:** 20/100 (low)
- **Website:** https://huggingface.co/docs/hub/en/mcp
- **Documentation:** https://huggingface.co/docs/hub/en/mcp
- **Last updated:** 2026-09-02
- **JSON:** https://catalog.anomity.ai/api/entries/mcp/hugging-face-mcp-server

## Description

Hugging Face's official server exposes models, datasets, Spaces, and inference to agents, so an assistant can search the hub, read model cards, and call hosted inference endpoints as tools.

Capabilities are outbound network access and credential access for the hub token. The supply-chain angle is the one to think about: an agent that can discover and invoke arbitrary community models and Spaces is an agent whose behaviour depends on artifacts nobody on your team reviewed. Model cards and dataset descriptions are also free text reaching the model's context. Prefer allow-listing the models an assistant may call over granting open hub access.

## Why it scored 20

The score starts at the catalog's neutral base of 50 and moves only through the signals below. The formula is published at https://catalog.anomity.ai/about — there is no model and no hidden heuristic.

| Signal | Contribution | Severity | Evidence |
| --- | --- | --- | --- |
| Published by the vendor | -40 | trust offset |  |
| 1 high-risk capability: credentials:access | +10 | high |  |

Clamped result: **20/100**, band **low**.

## Capabilities

| Capability | Name | Security implication |
| --- | --- | --- |
| `network:outbound` | Outbound network | Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access. |
| `credentials:access` | Credentials access | Reads provider API keys, OAuth tokens, or other secrets from the host keychain or environment. |

## Related MCP servers

- [Airtable MCP Server](https://catalog.anomity.ai/mcp/airtable-mcp-server) — risk 45 (medium)
- [Cloudflare MCP Server](https://catalog.anomity.ai/mcp/cloudflare-mcp-server) — risk 45 (medium)
- [ElevenLabs MCP Server](https://catalog.anomity.ai/mcp/elevenlabs-mcp-server) — risk 45 (medium)
- [MiniMax MCP Server](https://catalog.anomity.ai/mcp/minimax-mcp-server) — risk 45 (medium)
- [MongoDB MCP Server](https://catalog.anomity.ai/mcp/mongodb-mcp-server) — risk 45 (medium)
- [Neon MCP Server](https://catalog.anomity.ai/mcp/neon-mcp-server) — risk 45 (medium)

---

Source: Anomity Catalog (https://catalog.anomity.ai/). Scoring methodology: https://catalog.anomity.ai/about. Machine-readable index: https://catalog.anomity.ai/llms.txt · https://catalog.anomity.ai/openapi.json
